Service resilience

Backups, recovery, monitoring, change rollback, outages, and security events.

01

Are production databases backed up?

Yes. We take daily database backups, keep them in separate protected storage, and retain them for 30 days.

Backups protect service recovery. They are not a live archive that staff edit record by record. Deleted data ages out as backup copies expire.

02

What are the recovery targets?

We aim to restore the API within 15 minutes and the database within one hour.

For the database, our recovery point is the last daily backup. These are our operating goals, not a customer SLA unless a contract says otherwise.

03

Do you test backups and recovery?

Our policies require planned database restore tests and service recovery exercises.

Database restores, service restarts, full rebuilds, and security incident exercises have their own checks. A written schedule is not proof that a test took place.

Ask us for the latest completed test record if your review needs proof.

04

How are bad releases handled?

We use health checks and can return to the prior working service version.

The container setup separates the API, background jobs, task schedule, queue, and web entry point. Health checks test the service before and after a release.

05

How does Graph One handle a security incident?

We follow a written process for triage, containment, evidence, recovery, and notice.

We assess the data, people, and systems at risk. We tell customers and authorities when law or contract requires notice. Under the GDPR, notice to an authority may be due within 72 hours after awareness when the legal test is met.

06

When will a customer hear about a data breach?

Our DPA requires us to tell the customer without undue delay after we learn of a breach of customer data.

We share the facts we have, the likely effect, and the steps taken or planned. We add details as the review continues.

The 72-hour GDPR rule applies to notice to a regulator when its legal test is met. It does not let us wait 72 hours before telling a customer.

07

Where can a customer ask about an outage?

Email contact@graph.one for current service and incident details.

We do not use this trust center as a live service status feed.